Security Data Sheet

MCP Connector for Revit

Version 3.7.1, reviewed 27 September 2026.

What it does

A Revit add-in that lets your existing AI assistant read and edit the model that is open on the user's machine. You bring your own AI subscription. Supported on Revit 2022 to 2027.

How edits are controlled

The connector has no scheduler or background task of its own. It acts only when a program running under the same Windows account calls it, normally your AI client, and only after a user has switched the connection on in Revit. Whether you approve each call is set in the AI client.

The free tier cannot create or delete model elements or change their parameters. Its tools query and report on the model, change the selection and the active view, and can hide or isolate elements in a view. Hiding is temporary unless the call asks for a permanent hide in that view, which can be undone.

Pro tools that modify the model run inside standard Revit transactions, so each change appears in the Revit undo history and can be reversed with Undo. A step that fails is rolled back rather than left half made. Tools that work through many items, such as purges, warning fixes and batch edits, can skip an item that fails, keep the rest and report what was skipped, and some of them record more than one undo step. Saving, synchronising, enabling worksharing and writing files cannot be undone.

Where Revit would stop to show a warning, the connector accepts it so the tool can complete unattended. When Revit reports an error, many modelling tools roll the change back and return Revit's message. Other tools, including the warning fixes, apply Revit's own default resolution, which can delete, unjoin or unconstrain the elements involved. Errors with no resolution roll the change back.

The connector never saves, synchronises or relinquishes on its own. Those actions happen only through the tools whose purpose is to save, save as, compact, synchronise, relinquish, close or enable worksharing, and there is no autosave or timed synchronisation. The relinquish tool saves the local file first unless told not to. Family tools save family files only to a path named in the call, or back to the file the family was opened from. Worksharing permissions and element ownership apply to AI-driven changes exactly as they do to manual ones: the connector never takes ownership of another user's elements, and if a change touches one, Revit refuses it and the tool reports the failure.

Where model data goes

To whichever AI provider you already use, under your existing contract with that provider. AUTOM8LABS never receives your model data, never stores it, and is not a processor of it.

The add-in runs inside Revit on the workstation. The component that talks to your AI client has no third-party dependencies and makes no outbound network connections of its own.

What AUTOM8LABS receives

Licence activation, validation and release Licence key, product code, a hashed machine identifier, the Windows machine name, the version number and a random session identifier. Installs with no licence make no licence-related connection at all.

The machine identifier is a SHA-256 hash of hardware identifiers, or of the machine and account names where Windows cannot supply them. The underlying values never leave the machine.

What is stored

Model contentNever received or stored
File names and pathsNever received or stored
Licence recordsLicence key, hashed machine identifier, machine name and client version. Held for the duration of the licence and deleted on request
Payment recordsStripe for website purchases, Autodesk for store purchases. AUTOM8LABS does not store card data

On the workstation

  • No listening port. The add-in communicates with your AI client over a Windows named pipe, not a network socket.
  • Access restricted to the same Windows user. On Revit 2025 and later the pipe is opened current-user-only, so Windows scopes it to the account Revit is running under. On Revit 2022 to 2024 the pipe carries a single access control entry for that same account, and if the account cannot be resolved no pipe is created. On every version the connector's bridge checks that the pipe belongs to that account before connecting. Any program running under that account can use the pipe.
  • No log file by default. Diagnostics are off unless a user sets an environment variable for troubleshooting. When enabled, the log records connector events and, in the most detailed mode, the start of each tool request, which can include model file paths, element identifiers and text. It never leaves the machine.
  • Stored credentials are encrypted. The licence cache, which also holds the pack entitlement, is protected with Windows DPAPI at machine scope, so a copy taken to another computer cannot be read. A key placed by IT for pre-deployment stays unencrypted until it is first validated.
  • Adds itself to AI apps. Switching the connection on registers the connector with each supported AI app found for that Windows user, including Codex inside WSL, which it reaches by running wsl.exe. Switching it off removes those entries. Each time Revit starts, the connector repairs its own entry if the path has moved, and changes nothing else in those files.
  • No elevated privileges are required at runtime. Installation needs administrator rights once.

Supply chain

All third-party components are widely used libraries from the official NuGet ecosystem. Every component declares a licence. All are MIT except one, which is Apache-2.0. There are no copyleft licences in the shipped product.

A CycloneDX Software Bill of Materials is produced for each supported Revit version, because the dependency set differs between them. The bridge ships the .NET runtime and no other third-party code. At version 3.7.1, checked on 27 September 2026, no shipped component carries a known vulnerability.

SBOMs are available on request from [email protected].

Assurance

Every AUTOM8LABS binary and the installer are code-signed as AUTOM8LABS LTD through Azure Trusted Signing. Third-party libraries ship as their publishers release them.

See the Trust Center for the full assurance position and the sub-processor list.